meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, January 15th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 15 January 2021

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Dynamic Excel 4 Analysis; NTFS Corruption; Cisco Vulnerabilities

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, January 15th, 2021 edition of the Sandtonet Storm Center's Stormcast. My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida.

0:14.1

So yesterday, I talked about Hankitovich, was sort of a run-of-the-mill malware that relied on the victims to enable macros and very typical

0:23.3

sort of mass emailed malver. Well, today we sort of have the counterpart, Boyan, as part of his

0:29.7

day job ran into an Excel spreadsheet that was used in a spearfishing attack and, well, also relied on the victim-enabling

0:40.6

macros.

0:41.6

Now, this was one of those Excel for macros, as it turned out, and a bit difficult or

0:49.8

more difficult than usual to actually analyze.

1:00.0

In these targeted attacks, you often, of course, find more custom methodologies being used in order to evade various defenses, and this is essentially what Boyan had to deal with here,

1:07.0

and he's walking you step by step through how he solved the various challenges

1:12.6

that the attacker put up here in order to prevent reverse analysis of the malware.

1:18.6

In the end, Boyan had to resort to dynamic analysis, which essentially just means you run the

1:24.6

macro and see what it does. So often you're often you're using debuggers for Excel for Macro as well.

1:31.4

There isn't really sort of a debugger per se.

1:34.4

So Boyan shows how he coerced Excel into essentially acting as a debugger, inserting breakpoints

1:42.5

by taking advantage of the halt command that's available

1:46.2

in Excel. So of course, if you render something similar, let us know and let us know if you

1:52.5

find this particular article helpful. Then we've got an interesting vulnerability that's currently

1:59.2

unpatched and exploitable in Windows

2:03.6

that appears to corrupt NTFS volumes, but actually a reboot usually fixes the problem.

2:11.6

So as soon as, for example, you're changing to a directory with that name, even if the directory doesn't

2:18.5

exist, you are getting an error message saying that the file or directory is corrupted

2:24.8

and unreadable and the system will reboot.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.